Arbitrary code execution resp. escalation of privilege with Mozilla's SETUP.EXE

2015-10-28 Thread Stefan Kanthak
Hi @ll, Mozilla's (executable) full setup packages for Windows allow arbitrary code execution resp. escalation of privilege: their SETUP.EXE loads SHFOLDER.DLL ['] from a temporary (sub)directory "%TEMP%\7zS.tmp\" created during self-extraction of the full setup packages. This vulnerability is we

[SECURITY] [DSA 3381-1] openjdk-7 security update

2015-10-28 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-3381-1 secur...@debian.org https://www.debian.org/security/ Moritz Muehlenhoff October 27, 2015

[SECURITY] [DSA 3380-1] php5 security update

2015-10-28 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-3380-1 secur...@debian.org https://www.debian.org/security/ Florian Weimer October 27, 2015